Aggregates CVE and security vulnerability intelligence across all libmodbus-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Historical issues mainly involve vendor risk buffer overflow and vendor risk memory corruption and related problems; some flaws may lead to vendor impact application crash, affecting vendor surface software deployment scenarios.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2024-10918 | Stack-based Buffer Overflow vulnerability in libmodbus v3.1.10 allows to overflow the buffer allocated for the Modbus response if the function tries to reply to a Modbus request with an unexpected length. | [email protected] | 4.8 | 0.09% | 2025-02-27 | 2025-11-03 |
| CVE-2024-36845 | An invalid pointer in the modbus_receive() function of libmodbus v3.1.6 allows attackers to cause a Denial of Service (DoS) via a crafted message sent to the unit-test-server. | [email protected] | 4.3 | 0.26% | 2024-05-31 | 2025-11-03 |
| CVE-2024-36844 | libmodbus v3.1.6 was discovered to contain a use-after-free via the ctx->backend pointer. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted message sent to the unit-test-server. | [email protected] | 7.5 | 0.53% | 2024-05-31 | 2025-11-03 |
| CVE-2024-36843 | libmodbus v3.1.6 was discovered to contain a heap overflow via the modbus_mapping_free() function. | [email protected] | 7.5 | 0.75% | 2024-05-31 | 2025-11-03 |
| CVE-2024-34244 | libmodbus v3.1.10 is vulnerable to Buffer Overflow via the modbus_write_bits function. This issue can be triggered when the function is fed with specially crafted input, which leads to out-of-bounds read and can potentially cause a crash or other unintended behaviors. | [email protected] | 7.5 | 0.73% | 2024-05-08 | 2025-05-05 |
| CVE-2023-26793 | libmodbus v3.1.10 has a heap-based buffer overflow vulnerability in read_io_status function in src/modbus.c. | [email protected] | 9.8 | 0.89% | 2024-05-01 | 2025-05-05 |
| CVE-2022-0367 | A heap-based buffer overflow flaw was found in libmodbus in function modbus_reply() in src/modbus.c. | [email protected] | 7.8 | 0.05% | 2022-08-29 | 2025-11-03 |
| CVE-2019-14463 | An issue was discovered in libmodbus before 3.0.7 and 3.1.x before 3.1.5. There is an out-of-bounds read for the MODBUS_FC_WRITE_MULTIPLE_REGISTERS case, aka VD-1301. | [email protected] | 9.1 | 0.92% | 2019-07-31 | 2024-11-21 |
| CVE-2019-14462 | An issue was discovered in libmodbus before 3.0.7 and 3.1.x before 3.1.5. There is an out-of-bounds read for the MODBUS_FC_WRITE_MULTIPLE_COILS case, aka VD-1302. | [email protected] | 9.1 | 0.90% | 2019-07-31 | 2024-11-21 |